TradePages

Data Processing Addendum

Last updated: July 14, 2026 · Version 1.0

This Data Processing Addendum ("DPA") is part of, and incorporated by reference into, the Terms of Service (the "Agreement") between you ("Customer," the business using the Service) and Real Estate Labs, LLC d/b/a Trade Pages ("Company"). It applies where Company processes Customer Data on Customer's behalf. If there is a conflict between this DPA and the rest of the Agreement regarding the processing of Customer Data, this DPA controls.

1. Roles of the parties

For Customer Data — information about Customer's own customers, leads, bookings, invoices, job records, and site-visitor contact-form submissions — Customer is the "controller"/"business," and Company is the "processor"/"service provider," as those terms are used under applicable U.S. state privacy laws (including the CCPA/CPRA, VCDPA, Colorado Privacy Act, CTDPA, UCPA, TDPSA, and their analogs). Company processes Customer Data only to provide the Service and only on Customer's documented instructions (which include the Agreement and Customer's use of the Service's features).

2. Company's obligations

Company will:

a. Purpose limitation. Process Customer Data solely to provide, maintain, secure, and support the Service for Customer, and for no other purpose.

b. No sale; no independent use. Not sell or share Customer Data, and not retain, use, or disclose Customer Data for any purpose other than performing the Service — including not for Company's own commercial purposes and not to build or enrich any independent product or profile.

c. No cross-customer combination. Not combine Customer Data with the data of other, unrelated Trade Pages businesses, except as permitted by law to provide the Service to Customer.

d. Confidentiality. Ensure that personnel authorized to process Customer Data are bound by confidentiality obligations.

e. Security. Implement and maintain reasonable administrative, technical, and organizational measures designed to protect Customer Data against unauthorized access, loss, or disclosure, appropriate to the nature of the data.

f. Assistance. Provide reasonable assistance to Customer in responding to End Customers' privacy requests (access, deletion, correction, portability, opt-out) and in meeting Customer's own security, breach-notification, and (where applicable) data-protection-assessment obligations.

g. Breach notification. Notify Customer without undue delay after becoming aware of a confirmed breach of security leading to the unauthorized access, loss, or disclosure of Customer Data, and provide information reasonably available to Company to assist Customer's response.

3. Subprocessors

Customer authorizes Company to engage the subprocessors reasonably necessary to provide the Service. As of the date of this DPA, Company's subprocessors include:

Company will impose data-protection obligations on its subprocessors that are substantially consistent with this DPA, and remains responsible for its subprocessors' performance. Company will make available an updated subprocessor list on request or through the Service and will give Customer a reasonable means to learn of new subprocessors.

4. Customer's responsibilities

Customer is responsible for the accuracy and lawfulness of the Customer Data it collects and uploads, for providing any notices and obtaining any consents required to collect and process it (including any consent to contact End Customers by email or text), and for issuing lawful processing instructions. Customer will not use the Service to process sensitive categories of data beyond what the Service is designed to handle.

5. Data subject and consumer requests

If Company receives a request from an End Customer to exercise privacy rights regarding Customer Data, Company will, to the extent legally permitted, refer the request to Customer and assist Customer in responding as its processor. Customer is responsible for responding to its End Customers' requests.

6. Return and deletion

On termination or cancellation of the Service, Company will, at Customer's option and consistent with the Terms, make Customer Data available for export and will retain it for thirty (30) days, after which Company may delete Customer Data, except for copies required to be retained by law or held in routine backups that are deleted on a rolling basis.

7. Audit / verification

Company will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and will reasonably cooperate with Customer's good-faith verification of Company's data practices, no more than once per year and subject to reasonable confidentiality and security conditions.

8. General

This DPA is governed by the same law and dispute-resolution terms as the Agreement (Michigan law; arbitration/venue per the Terms). If any provision is unenforceable, the remainder stays in effect. This DPA does not grant Customer any rights beyond those in the Agreement except as expressly stated.

Contact: Real Estate Labs, LLC d/b/a Trade Pages · legal@mytradepage.com